Re: One Cookie/Multiple Domains

by "Kehvan M. Zydhek" <kehvan(at)zydhek.net>

 Date:  Sun, 30 Apr 2000 18:11:56 -0700
 To:  "David Clapper" <dclapper(at)clioassociates.com>,
<hwg-techniques(at)hwg.org>
 References:  clapper02
  todo: View Thread, Original
David,

While I know what you request can be done, I personally don;t know how to do
it. I'm writing only to point out that what you're describing is pretty much
the reason why cookies are so feared -- the ability for one domain to read
another domain's cookie is the basis for all the whining about them lately.
Cookies are not supposed to be able to be read except by the domain that
wrote them. What you're asking for is a violation of their design, however
innocent the reason, and why many people turn cookies off.

My suggestion is that you let you client know this, and let them know that
their registered users may have to re-enter some or all of their code for
the new domain. That would at least not violate the "rules" of cookies.

Like I said, it's possible, but doing so is bad practice, no matter the
reason.

Just my opinion.

Kehvan M. Zydhek


----- Original Message -----
From: "David Clapper" <dclapper(at)clioassociates.com>
To: <hwg-techniques(at)hwg.org>
Sent: Sunday, April 30, 2000 4:45 PM
Subject: One Cookie/Multiple Domains


> Hello all,
>
> One of my customers has multiple domain names pointing to their single
> website.  They want to use a cookie allow "registered users" to avoid
> logging on.
>
> The issue is, they have been promoting themselves under domain xxx.com.
> They now want to use yyy.com, and want the cookie to be valid for both
> domains.  Can this be done?  If so, how?
>
> TIA ... .
>
>

HWG hwg-techniques mailing list archives, maintained by Webmasters @ IWA